Skip to content

812:marked:Regular Expression Denial of Service #293

@marshyski

Description

@marshyski

No CVE
CWE CWE-400
References: - GitHub PR

  • Snyk Report
    Versions of marked prior to 0.6.2 and later than 0.3.14 are vulnerable to Regular Expression Denial of Service. Email addresses may be evaluated in quadratic time, allowing attackers to potentially crash the node process due to resource exhaustion.
    @marshyski

Metadata

Metadata

Assignees

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions